BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive

Check Point Research Version 1 original current

Imported from official source

Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 – without exploits, vulnerabilities, or memory corruption? …

This version

Version
1 of 1
Recorded
September 18, 2026 11:35
Change
Initial
Content hash
bdbd4c94cc9054e099ca97d5ff858a60
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.